pull down to refresh

Here is a healthy -- if unpleasant -- dose of reality about coinjoins courtesy of @spiral:

For real-world transaction graphs, subject to the constraints of the UTXO model, the naive anonymity set size estimate based on counting equivalent sibling outputs can be misleading and provide a false sense of privacy, even under fairly generous assumptions. This is even more true when the adversary has access to higher-quality auxiliary information, and when attacking the privacy of multiple users, not just one specific target.

Spiral's newsletter is running a series on privacy in the UTXO world and it is depressing, even if needed. We would all do well to remember that attackers are constrained by nothing other than a desire to determine information about us.

Some of the examples in this article were not terribly clear and left me confused, but it makes plenty of solid points. Most recently, I was thinking about these things in relation to Coldcard and the likelihood that a great number of utxos involved in the theft are likely to get doxxed in some manner. As the data leaks and breaches pile up, correlating data to identify us is going to get ever easier.

Seems like we really need to focus on increasing the size of our anonymity set.

56 sats \ 0 replies \ @optimism 12h
we really need to focus on increasing the size of our anonymity set

What are you trying to protect against?

The article swoops everything together, not really making a distinction between a nation state operating a dragnet and the ex spouse (fwiw the latter is way nastier.)

I don't think that if you're in the US, you can protect against the NSA, and excluding them is useful because for anything else, including "state of the art" chainalysis shit, you can probably beat with a small toolset and a good plan, the most important feature being your patience and knowing (not assuming or believing) that your tools are really up to the task, not just some bs some dude said. And that's probably where the pain really is at: I can't tell you which tools are good, because you can't take my word for it. And no, you cannot take anyone else's word for it either.

What we can talk about is weaknesses though, especially process weaknesses. So let's do that sometimes.

reply

I’m glad people are analyzing privacy and talking about this.

The good news is that you don’t need to be perfect. You need the cost of finding you to be higher than the perceived reward. Even with AI when you can automate a lot more complex analysis it still costs tokens.

reply

Yeah, it’s a harsh reality, but an important one. Privacy is only as strong as the information that can be connected back to you.

reply
12 sats \ 0 replies \ @npub1zapsats 13h -100 sats

First of all are you goading kruw to downzap this lol

And second of all does lightning have a place to play in obfuscation of activity, when onchain gymnastics as you allude to, becomes ever harder